13% of ISO 45001 you already have
PCI SSF already covers about 13% of ISO 45001, leaving
34 of 39 controls as genuinely new work.
Already covered 0
Likely covered 5
New work 34
No control in PCI SSF
maps directly to one in ISO 45001. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in PCI SSF reaches these. This is the list to scope.
ISO45001-01OH&S policy and commitment
ISO45001-04OH&S objectives and action plans
ISO45001-05Worker consultation and participation
ISO45001-06Elimination and substitution of hazards
ISO45001-07Engineering and administrative controls
ISO45001-08Personal protective equipment management
ISO45001-09Emergency preparedness and response
ISO45001-10Contractor and visitor safety management
ISO45001-10.2Incident, nonconformity and corrective action
ISO45001-10.3Continual improvement
ISO45001-11Incident investigation and reporting
ISO45001-12OH&S monitoring and measurement
ISO45001-13Internal OH&S audit program
ISO45001-14Management review and continual improvement
ISO45001-4.1Understanding the organization and its context
ISO45001-4.2Needs and expectations of workers and interested parties
ISO45001-4.3Determining scope of OH&S management system
ISO45001-5.3Roles, responsibilities and authorities
ISO45001-5.4Consultation and participation of workers
ISO45001-6.1.2Hazard identification and assessment of risks
ISO45001-6.1.3Determination of legal and other requirements
ISO45001-6.1.4Planning action
ISO45001-6.2OH&S objectives and planning to achieve them
ISO45001-7.4Communication
ISO45001-8.1.2Eliminating hazards and reducing OH&S risks
ISO45001-8.1.4Procurement and contractors
ISO45001-8.2Emergency preparedness and response
ISO45001-9.1Monitoring, measurement, analysis and evaluation
ISO45001-9.1.2Evaluation of compliance
ISO45001-9.2Internal audit
ISO45001-9.3Management review
Show the 5 you already have
ISO45001-02Hazard identification and risk assessment
ISO45001-03Legal and regulatory compliance
ISO45001-15Corrective actions and lessons learned
ISO45001-5.1Leadership and commitment
ISO45001-8.1.3Management of change
How this is calculated
Already covered means a mapping runs from a control in PCI SSF to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition